{"record":{"id":"1e154463a89743d2","repo":"paperclipai/paperclip","slug":"networkscope-allowlist-requires-at-least-one-val","errorCode":null,"errorMessage":"networkScope=\"allowlist\" requires at least one valid networkAllowlist hostname or HTTP(S) networkTrustedUrl.","messagePattern":"networkScope=\"allowlist\" requires at least one valid networkAllowlist hostname or HTTP\\(S\\) networkTrustedUrl\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/adapter-utils/src/local-process-sandbox.ts","lineNumber":241,"sourceCode":"    \"Content-Type: application/json; charset=utf-8\",\n    `Content-Length: ${Buffer.byteLength(body)}`,\n    \"\",\n    body,\n  ].join(\"\\r\\n\");\n}\n\nasync function startNetworkAllowlistProxy(\n  allowlist: string[],\n  trustedUrls: string[],\n  socketPath: string,\n): Promise<NetworkAllowlistProxy> {\n  assertUnixSocketPathLength(socketPath);\n  const rules = [\n    ...allowlist.map(parseNetworkAllowlistEntry),\n    ...trustedUrls.map(parseTrustedNetworkUrl).filter((rule): rule is NetworkAllowlistRule => rule !== null),\n  ];\n  if (rules.length === 0) {\n    throw new Error(\n      'networkScope=\"allowlist\" requires at least one valid networkAllowlist hostname or HTTP(S) networkTrustedUrl.',\n    );\n  }\n  const server = http.createServer((request, response) => {\n    let target: URL;\n    try {\n      target = new URL(request.url ?? \"\");\n    } catch {\n      writeProxyError(response, 400, \"invalid_request_url\", \"Paperclip sandbox proxy requires an absolute request URL.\");\n      return;\n    }\n    const port = target.port || (target.protocol === \"https:\" ? \"443\" : \"80\");\n    if (target.protocol !== \"http:\") {\n      writeProxyError(response, 400, \"https_requires_connect\", \"HTTPS targets must use CONNECT through the Paperclip sandbox proxy.\");\n      return;\n    }\n    if (!isNetworkTargetAllowed(target.hostname, port, rules)) {\n      writeProxyError(response, 403, \"network_target_denied\", \"Network target denied by Paperclip sandbox policy.\");","sourceCodeStart":223,"sourceCodeEnd":259,"githubUrl":"https://github.com/paperclipai/paperclip/blob/120ae5428fa29bee300bcf806491cd4d965fbb7c/packages/adapter-utils/src/local-process-sandbox.ts#L223-L259","documentation":"startNetworkAllowlistProxy combined the allowlist and trusted-URL rules and got zero rules, so an 'allowlist' network scope would allow nothing and is treated as misconfiguration.","triggerScenarios":"Thrown at packages/adapter-utils/src/local-process-sandbox.ts:241 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Add at least one valid networkAllowlist hostname or HTTP(S) networkTrustedUrl when using networkScope=\"allowlist\".","Set networkScope to \"deny\" if no network access is needed."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"120ae5428fa29bee300bcf806491cd4d965fbb7c","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}